Crypto KMS
    Preparing search index...

    Class AwsKmsProvider

    AWS KMS adapter.

    Wraps the @aws-sdk/client-kms SDK to provide the unified KmsProvider interface. Install @aws-sdk/client-kms as a peer dependency.

    const provider = new AwsKmsProvider({ region: "us-east-1" });
    const key = await provider.createKey("aes-256-gcm", "encrypt");
    const encrypted = await provider.encrypt(key.keyId, plaintext);

    Implements

    Index
    name: "aws"

    Provider identifier.

    • List all KMS keys, optionally filtered by usage or enabled state.

      Parameters

      • Optional_filters: { usage?: string; enabled?: boolean }

      Returns Promise<KmsKeyMetadata[]>

    • Create a new KMS key with the given algorithm and usage.

      Parameters

      • algorithm: string
      • usage: "encrypt" | "sign" | "wrap"
      • Optionalmetadata: Record<string, string>

      Returns Promise<KmsKeyMetadata>

    • Disable a KMS key so it cannot be used for operations.

      Parameters

      • keyId: string

      Returns Promise<void>

    • Schedule a KMS key for deletion after a pending window.

      Parameters

      • keyId: string
      • pendingWindowDays: number = 30

      Returns Promise<void>

    • Encrypt plaintext using a KMS key, with optional encryption context.

      Parameters

      • keyId: string
      • plaintext: Uint8Array
      • Optionalcontext: Record<string, string>

      Returns Promise<KmsEncryptResult>

    • Decrypt ciphertext using a KMS key, with optional encryption context.

      Parameters

      • keyId: string
      • ciphertext: string
      • Optionalcontext: Record<string, string>

      Returns Promise<KmsDecryptResult>

    • Sign data using a KMS signing key.

      Parameters

      • keyId: string
      • data: Uint8Array
      • algorithm: string = "RSASSA_PSS_SHA_256"

      Returns Promise<KmsSignResult>

    • Verify a signature against data using a KMS signing key.

      Parameters

      • keyId: string
      • data: Uint8Array
      • signature: string
      • algorithm: string = "RSASSA_PSS_SHA_256"

      Returns Promise<boolean>

    • Generate a data encryption key (DEK) wrapped by the managed key.

      Parameters

      • keyId: string
      • keySpec: string = "AES_256"

      Returns Promise<{ plaintext: Uint8Array; ciphertext: string }>